Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
vulns-2026-fatfs-chance — Documented security vulnerabilities in the FatFs embedded filesystem library with CVE details, fuzzing harness, exploit disk-image generator, and supply-chain impact analysis across dozens of downstream firmware projects. | Kitploit
Tools/GitHubGitHub/runzeroinc/vulns-2026-fatfs-chance
Embedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationFuzzingHardware SecurityBinary AnalysisSupply Chain SecurityPapers & Research

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Learning & Education
Firmware Analysis
GitHubrunzeroinc/vulns-2026-fatfs-chance

vulns-2026-fatfs-chance

Documented security vulnerabilities in the FatFs embedded filesystem library with CVE details, fuzzing harness, exploit disk-image generator, and supply-chain impact analysis across dozens of downstream firmware projects.

View Repository
419462 months agoReviewed by Kitploit

ELM FatFs Vulnerability Research

This repository documents six confirmed security vulnerabilities in FatFs along with a test harness, fuzzer, and standalone exploit disk-image generator.

The original FatFs source code can be found in the FatFs-R0.16 directory.

This project is a return to a security assessment from 2017, when a manual audit and multi-day fuzzing effort identified some basic, but not interesting bugs in the FatFs driver. Nine years later, in March of 2026, we revisited this project using Visual Studio Code, GitHub Copilot in "auto" mode, and some basic prompts, without any specific loops, harnesses, or skills. The results were surprising - bugs that were overlooked during the manual audit became trivial to find, by using the LLM to automatically build a fuzzer with novel inputs. Not only did this effort find interesting bugs, it also automated the process of validating exploitable across different embedded developent scenarios.

Please see the following files for detailed notes:

  • 00_INITIAL.md: Initial investigation and findings
  • 01_PROJECTS.md: Project enumeration and FatFs version survey
  • 02_CRITICAL.md: Analysis of highest-impact projects

What is FatFs?

FatFs is a portable, royalty-free FAT/exFAT filesystem library written in C by ChaN (elm-chan.org). It is designed for resource-constrained embedded systems with no OS dependency and is typically compiled directly into firmware. It supports FAT12, FAT16, FAT32, and exFAT, as well as optional LFN (Long File Name) and GPT partition support.

Because FatFs is small, self-contained, and permissively licensed, it has become the de-facto standard FAT implementation for microcontroller firmware. The library is vendored verbatim into official SDKs, RTOSes, bootloaders, and application frameworks - meaning a single upstream vulnerability propagates to every downstream project that copied ff.c.

Major Projects

The following projects have been confirmed to bundle a vulnerable version of FatFs. See 02_CRITICAL.md for the complete analysis, per-project propagation paths, and security contact information.

ProjectStarsFatFs VersionBugs
espressif/esp-idf17,655R0.16CVE-2026-6682
STMicroelectronics/stm32-mw-fatfsall STM32CubeR0.15 w/p2CVE-2026-6682, CVE-2026-6683, CVE-2026-6686, CVE-2026-6687
zephyrproject-rtos/zephyr14,820R0.16CVE-2026-6683, CVE-2026-6687, CVE-2026-6688
micropython/micropython21,583R0.13c (2019)CVE-2026-6682, CVE-2026-6683, CVE-2026-6684, CVE-2026-6686, CVE-2026-6687
ArduPilot/ardupilot14,743R0.14bCVE-2026-6682, CVE-2026-6683, CVE-2026-6686, CVE-2026-6687
RT-Thread/rt-thread11,862R0.16CVE-2026-6683, CVE-2026-6686
nodemcu/nodemcu-firmware7,903variesCVE-2026-6688
RIOT-OS/RIOT5,701R0.15CVE-2026-6682, CVE-2026-6683, CVE-2026-6686, CVE-2026-6687
ARMmbed/mbed-os4,837R0.14bCVE-2026-6682, CVE-2026-6683, CVE-2026-6686
sbabic/swupdate1,780R0.16CVE-2026-6683
rsta2/circle2,222tbdCVE-2026-6684
hugen79/NanoVNA-H695R0.15CVE-2026-6683
ChibiOS/ChibiOS833variesCVE-2026-6688
Samsung/TizenRT643R0.16CVE-2026-6683, CVE-2026-6688
adafruit/tinyuf2447tbdCVE-2026-6684, CVE-2026-6686
grblHAL/Plugin_SD_card475R0.16CVE-2026-6688
JcZou/StarryPilot315R0.16CVE-2026-6688
KeystoneHQ/keystone3-firmware199R0.16CVE-2026-6682
flysight/flysight44variesCVE-2026-6682, CVE-2026-6688
eugene-tarassov/vivado-risc-v1,061tbdCVE-2026-6684

CVE Summary

CVE IDShort TitleCWE
CVE-2026-6682Integer Overflow in FAT32 Volume MountCWE-190: Integer Overflow or Wraparound
CVE-2026-6683Divide-by-Zero in exFAT SyncCWE-369: Divide By Zero
CVE-2026-6684Infinite Loop in GPT Partition ScanCWE-835: Loop with Unreachable Exit Condition
CVE-2026-6686Use of Uninitialized Clusters After Seek Past EOFCWE-908: Use of Uninitialized Resource
CVE-2026-6687Stack Buffer Overflow via Uncapped exFAT Label LengthCWE-121: Stack-based Buffer Overflow
CVE-2026-6688Buffer Overflow via Unbounded LFN Filename CopyCWE-120: Buffer Copy without Checking Size of Input

Attacker Value

FatFs has no CVE history, no security mailing list, and no patch notification mechanism. Every downstream project that vendors ff.c must discover, triage, and patch these vulnerabilities independently, usually without knowing they are affected. That means the window between public disclosure and widespread remediation will be measured in years, not days. The practical attack surface is therefore not one software application or serbvice, but tens of millions of devices across dozens of independent codebases, many of which will never receive a patch.

The archetypal exploitation scenario is the evil SD card: an attacker with a few seconds of physical access swaps the storage medium in a device, from consumer cameras to drones, to 3-D printers to a thousand other product families. Every vulnerability in this set is triggerable by mounting a crafted FAT image, which nearly always happens automatically on insertion with no user interaction required. That said, physical access is not the only path.

Devices that ingest FAT-formatted update packages from a network source such as OTA update frameworks and drag-and-drop bootloader updates, are exploitable by any attacker who can deliver a malicious image to the update pipeline. Supply chain compromises, an AitM injection on a cleartext HTTP update feed, or a malicious image posted to a hobby firmware distribution portal. The OTA path is fully remote on any device that lacks end-to-end authenticated integrity verification of its update container prior to mounting it with FatFs.

Attacker Value by CVE

CVE-2026-6682 - Integer overflow leading to attacker-controlled read length

Download Tool